Create a bespoke document in minutes, or upload and review your own.
Get your first 2 documents free
Your data doesn't train Genie's AI
You keep IP ownership of your information
Third Party Data Processing Agreement
"I need a Third Party Data Processing Agreement for my UK-based software company that will be processing customer data for a large retail client, with specific provisions for cloud storage and automated data processing, to be effective from March 2025."
1. Parties: Identification of the data controller and data processor, including registered addresses and company details
2. Background: Context of the processing relationship and purpose of the agreement
3. Definitions: Definitions of key terms used throughout the agreement, including GDPR-specific terminology
4. Processor Obligations: Core obligations of the processor under Article 28 UK GDPR, including processing only on documented instructions
5. Security Measures: Requirements for technical and organizational security measures to protect personal data
6. Data Breach Procedures: Procedures for identifying, reporting and managing personal data breaches
7. Sub-processing: Conditions and requirements for engaging sub-processors
8. Data Subject Rights: Obligations to assist the controller in responding to data subject requests
9. Term and Termination: Duration of the agreement, termination rights and data deletion obligations
10. Liability and Indemnities: Allocation of liability between parties and indemnification provisions
1. International Transfers: Provisions governing transfers of personal data outside the UK/EEA, including appropriate safeguards
2. Industry-Specific Requirements: Additional obligations specific to regulated industries or sectors
3. Audit Rights: Enhanced audit provisions for controller oversight of processing activities
4. Insurance Requirements: Specific insurance obligations for data protection-related risks
1. Schedule 1 - Processing Details: Details of processing activities including nature, purpose, types of personal data and categories of data subjects
2. Schedule 2 - Technical and Organizational Measures: Detailed description of security measures implemented by the processor
3. Schedule 3 - Approved Sub-processors: List of pre-approved sub-processors and their processing activities
4. Schedule 4 - Transfer Mechanisms: Details of international transfer mechanisms and safeguards where applicable
5. Schedule 5 - Security Breach Notification Form: Template for reporting personal data breaches to the controller
Authors
Applicable Data Protection Laws
Authorised Sub-processor
Business Day
Controller
Data Protection Impact Assessment
Data Subject
Data Subject Request
EEA
Personal Data
Personal Data Breach
Processing
Processor
Restricted Transfer
Security Requirements
Services
Special Categories of Personal Data
Sub-processor
Supervisory Authority
Technical and Organisational Measures
Term
UK GDPR
Duration
Nature and Purpose of Processing
Processor Obligations
Controller Obligations
Sub-processing
Confidentiality
Security
Personal Data Breach
Data Subject Rights
Data Protection Impact Assessments
International Transfers
Audit Rights
Liability and Indemnification
Return or Deletion of Data
Term and Termination
Governing Law
Dispute Resolution
Force Majeure
Assignment
Find the exact document you need
Dpa Addendum
A UK-law compliant addendum defining data processing obligations between controllers and processors under GDPR and DPA 2018.
Joint Data Controller Agreement
A legally binding agreement under English and Welsh law that establishes responsibilities between organizations jointly controlling personal data processing.
Third Party Processor Agreement
A legally binding agreement under English and Welsh law governing the processing of personal data by a third party on behalf of a data controller.
Personal Data Collection Agreement
A legally binding agreement under English and Welsh law governing the collection and processing of personal data in compliance with UK GDPR and related legislation.
International Data Protection Agreement
A legally binding agreement under English and Welsh law governing international personal data processing and transfer arrangements between controllers and processors.
Data Sharing Agreement Controller To Processor
A legally binding agreement under English and Welsh law establishing terms for data processing between a controller and processor, ensuring UK GDPR compliance.
Processor To Processor Dpa
A legal agreement under English and Welsh law governing data processing arrangements between two processors, ensuring UK GDPR compliance.
Master Data Protection Agreement
A legal agreement under English and Welsh law governing the processing of personal data between organizations, ensuring compliance with UK data protection regulations.
Intra Group Data Transfer Agreement
A UK law-governed agreement regulating personal data transfers between entities within the same corporate group, ensuring compliance with UK data protection regulations.
Data Management Agreement
A legal agreement under English and Welsh law governing the terms of data handling and processing between parties, ensuring compliance with UK data protection regulations.
Data Controller To Data Controller Agreement
An English law agreement governing personal data sharing between two independent data controllers, ensuring UK GDPR compliance.
Commissioned Data Processing Agreement
A legal agreement under English and Welsh law governing the processing of personal data between a controller and processor, ensuring UK GDPR compliance.
Controller To Controller Dpa
A legal agreement under English and Welsh law governing personal data sharing between two independent data controllers, ensuring UK GDPR compliance.
Dpa Agreement
A legally binding agreement under English and Welsh law that governs the processing of personal data between a controller and processor, ensuring UK GDPR compliance.
Third Party Data Processing Agreement
An English law agreement governing the processing of personal data between a controller and processor under UK GDPR requirements.
Data Transfer Addendum
A legal document under English and Welsh law that governs the transfer of personal data between organizations in compliance with UK data protection regulations.
Supplier Data Processing Agreement
A legal agreement under English and Welsh law governing personal data processing arrangements between controllers and processors, ensuring UK GDPR compliance.
Personal Data Transfer Agreement
An England and Wales law-governed agreement establishing terms for compliant transfer of personal data between organizations under UK data protection regulations.
Controller Processor Agreement
A legal agreement under English and Welsh law governing the relationship between data controllers and processors, ensuring compliance with UK data protection requirements.
Order Processing Agreement
A legal agreement under English and Welsh law governing the processing of orders and associated data, ensuring compliance with UK data protection regulations.
Data Protection Agreement For Employees
A legally binding agreement under English and Welsh law governing the processing and protection of employee personal data in compliance with UK data protection legislation.
Affiliate Addendum
A supplementary legal document under English and Welsh law that modifies existing affiliate agreements, outlining additional terms and conditions for affiliate marketing relationships.
Sub Processing Agreement
An English law agreement governing the relationship between a processor and sub-processor for personal data processing activities.
Data Protection Addendum
A legal document under English and Welsh law that establishes data protection obligations between parties processing personal data in compliance with UK GDPR.
Data Transfer Agreement
A legal agreement under English and Welsh law governing the transfer of personal data between organizations, ensuring compliance with UK data protection regulations.
Download our whitepaper on the future of AI in Legal
Genie’s Security Promise
Genie is the safest place to draft. Here’s how we prioritise your privacy and security.
Your documents are private:
We do not train on your data; Genie’s AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
Our bank-grade security infrastructure undergoes regular external audits
We are ISO27001 certified, so your data is secure
Organizational security
You retain IP ownership of your documents
You have full control over your data and who gets to see it
Innovation in privacy:
Genie partnered with the Computational Privacy Department at Imperial College London
Together, we ran a £1 million research project on privacy and anonymity in legal contracts
Want to know more?
Visit our Trust Centre for more details and real-time security updates.
Read our Privacy Policy.